Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
phpMyPortal 3.0.0 RC3 - GLOBALS[CHEMINMODULES] Remote File Inclusion
CVE-2007-2594webappsphp
PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
CVE-2007-4596localwindows
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
CVE-2007-6179webappsphp
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
FaScript FaPhoto 1.0 - 'show.php' SQL Injection
CVE-2008-1714webappsphp
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
BuzzyWall 1.3.1 - 'id' Remote File Disclosure
CVE-2008-4759webappsphp
Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local fil
23RIESGO
abrir
ReferênciaVexDay Proof
acronis pxe server 2.0.0.1076 - Directory Traversal / Null Pointer
CVE-2008-1411remotewindows
The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Classifieds Script - Remote Database Disclosure
CVE-2008-7080webappsphp
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir
ReferênciaVexDay Proof
Free Photo Gallery Site Script - 'path' File Disclosure
CVE-2008-1730webappsphp
Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Ph
23RIESGO
abrir
ReferênciaVexDay Proof
Telekorn Signkorn Guestbook 1.3 - 'dir_path' Remote File Inclusion
CVE-2006-4788webappsphp
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, whe
23RIESGO
abrir
ReferênciaVexDay Proof
Blogator-script 0.95 - 'incl_page' Remote File Inclusion
CVE-2008-1760webappsphp
Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
CMS Creamotion - 'securite.php' Remote File Inclusion
CVE-2007-5298webappsphp
Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir
ReferênciaVexDay Proof
Blogator-script 0.95 - 'id_art' SQL Injection
CVE-2008-1763webappsphp
SQL injection vulnerability in _blogadata/include/sond_result.php in Blogator-script 0.95 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Album Starter 3.2 - Unchecked Local Buffer Overflow
CVE-2008-1765localwindows
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remot
28RIESGO
abrir
ReferênciaVexDay Proof
Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
CVE-2010-0425remotewindows
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2
60RIESGO
abrir
ReferênciaVexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
CVE-2007-6554webappsphp
Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
ChartDirector 4.1 - 'viewsource.php' File Disclosure
CVE-2008-1782webappsphp
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive file
23RIESGO
abrir
ReferênciaVexDay Proof
Ourgame GLWorld 2.x - 'hgs_startNotify()' ActiveX Buffer Overflow
CVE-2008-0647remotewindows
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.
23RIESGO
abrir
ReferênciaVexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
CVE-2009-0328webappsasp
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RIESGO
abrir
ReferênciaVexDay Proof
Dragoon 0.1 - 'lng' Local File Inclusion
CVE-2008-1798webappsphp
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include a
23RIESGO
abrir
ReferênciaVexDay Proof
PPStream - 'PowerPlayer.dll 2.0.1.3829' ActiveX Remote Overflow
CVE-2007-4748remotewindows
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
CVE-2008-1801doslinux
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir
ReferênciaVexDay Proof
μTorrent (uTorrent) / BitTorrent WebIU HTTP 1.7.7/6.0.1 - Range header Denial of Service
CVE-2008-0071doswindows
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Remote Buffer Overflow
CVE-2009-1611remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
CVE-2008-3578doswindows
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RIESGO
abrir
ReferênciaVexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
CVE-2008-1069webappsphp
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RIESGO
abrir
ReferênciaVexDay Proof
Maxum Rumpus 6.0 - Multiple Remote Buffer Overflow Vulnerabilities
CVE-2008-7078doswindows
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation f
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1325doswindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JoomlaXplorer 1.6.2 - Remote s
CVE-2008-1849webappsphp
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 an
23RIESGO
abrir
ReferênciaVexDay Proof
ASPPortal 3.1.1 - 'downloadid' SQL Injection
CVE-2006-1353webappsasp
Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.